CrowdStrike says it caught an insider sharing screenshots taken on internal systems with unnamed threat actors.
If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/BleepingComputer/statuses/115588709520660643 on your instance and quote it. (Note that quoting is not supported in Mastodon.)
RE: https://infosec.exchange/@BleepingComputer/115588709520660643
Crowdstrike stepped up from negligent insiders to malicious insiders. LMAO.
Oh, I'm sorry, Crowdstrike called them a "suspicious insider." Despite the investigation that "determined he shared pictures of his computer screen externally."
And the unnamed threat actors? FEISTY CUMSTAIN.
